Near real-time multi-party task authorization access control

ABSTRACT

A method and apparatus are used in determining authorization to perform tasks in a computer environment, and specifically requiring multiple parties to authorize a task before access is granted. The present system provides for substantially real time communication to a second party authorizer when a task owner is attempting to perform a task.

This application claims the benefit of U.S. Provisional Patent Application No. 60/508,444, filed Oct. 1, 2003, which is incorporated by reference herein in its entirety.

TECHNICAL FIELD OF THE INVENTION

The present invention relates in general to methods and apparatus used in determining authorization to perform tasks in a computer environment and more particularly to methods and apparatus for requiring multiple parties to authorize a task before authorization is granted.

BACKGROUND OF THE INVENTION

In recent years, computers have proliferated in all parts of worldwide society, including but not limited to, banking, financial services, business, education, and various governmental entities. For instance and without limitation, these computer systems allow individuals to consummate financial transactions, to exchange confidential scientific and/or medical data, and to exchange highly proprietary business planning data. Hence, these computer systems require and/or allow very sensitive and confidential data to be stored and transmitted over great geographic distances. Computer systems have also been integrated with the command and control of much of the critical infrastructure of the world including power production and distribution, gas and oil production and distribution, transportation, communications, and medical as well as others. Proper and secure functioning of computer systems is critical for the functioning of practically every system today.

Moreover, the rise of multinational communications networks, such as the publicly available Internet communications system, has truly made the world a smaller place by allowing these computers, separated by great geographic distances, to very easily communicate and exchange data. In essence, these worldwide communications channels/networks; sometimes collectively referred to as “the Information Superhighway” have electronically connected the peoples of the world—both the good and the very bad.

That is, while these computer systems have increased efficiency and greatly changed the manner in which we work and interact, they have been especially prone to unauthorized “break-ins”, viral destruction, and/or unauthorized data modifications. Accordingly, the rather sensitive and confidential data which is stored and used within these computer systems and transmitted between these computer systems has been the target of attack by people known as “hackers”, by high level and very sophisticated espionage and industrial spies, and by terrorists seeking high profile methods of causing destruction and fear. Computer access security and data transmission security has recently come to the forefront of importance and represents one of the great needs of our times.

Many attempts have been made to create and utilize various techniques to “ensure” that only authorized users are allowed to gain access to these respective computer systems. These prior techniques, while somewhat effective, suffer from various drawbacks.

For example, one such prior computer system security technique comprises the use of predetermined “passwords”. That is, according to this security technique, each computer system has a list of authorized passwords which must be communicated to it before access is given or allowed. In theory, one or more “trusted” system administrators distribute these “secret” passwords to a group of authorized users of a computer system. The “secret” nature of the passwords, in theory, prevents unauthorized users from accessing the computer system (since presumably these unauthorized users do not have the correct passwords). This technique is not very effective since oftentimes those authorized individuals mistakenly and unwittingly expose their password to an unauthorized user. Moreover, this technique of data security may be easily “broken” by a “hacker's” deliberate and concentrated attempt at automatically inputting, to the targeted computer, hundreds and perhaps thousands of passwords until an authorized password is created.

In addition to the prior password technique other, more sophisticated access techniques are known and used. For example, there are known techniques which require the possession of a physical object or feature, such as “access cards” which are “read” by a card reading device and biometric authentication techniques (e.g. requiring the initial input of such authorized user physical characteristics as fingerprints and eye patterns and the later comparison of these input patterns to those of a “would-be” user). Both of these prior techniques are relatively complicated, are relatively costly, and are prone to error, such as and without limitation, mistaken unauthorized entry due to their complexity. These techniques are also prone to unauthorized entry by use of counterfeit and/or stolen cards, objects, and fingerprint readers. Other prior data security techniques, such as encryption, attempt to prevent unauthorized use of transmitted data or unauthorized access to a computer system by modifying and/or changing the transmitted data in a certain manner, and/or requiring the transmission and receipt of modified data before access is granted. While somewhat effective, these prior encryption techniques are relatively costly and complicated and require one or more known “encryption keys” which are in constant exchange between users and which are themselves susceptible to theft and/or inadvertent disclosure.

There therefore exists a significant possibility that an individual's credentials for authentication or authorization can be compromised. In addition, there also exists the possibility of an authorized individual becoming compromised. Having an authorized individual become compromised is one of the most difficult security concerns to protect against.

The concept of separation of duties as a protection against a compromised party in a position of authority is well established in many applications. The key concept is that one person alone cannot complete a critical process. For example, in accounting, the same individual does not keep the books and audit them. Similarly, two signatures are often required on a check above a pre-determined limit. In banks, two keys are usually needed to open a safe deposit box. In the same vein, the same person who performs change management of a network should not be the one who audits the logs of what has happened in the network. Separation of duties should be a key part of a security policy.

Separation of duties has also become a key component of workflow design. Under this concept, no one person should have the ability or permission to complete all the tasks necessary for a critical process that could compromise the security of the company. If one party submits a network administration order, another person should have to approve the order. The same party that initiates a Change Management Request (CMR) should not approve the CMR.

Most of the current research on the use of separation of duties in access control systems is focused on ensuring that authorizations for tasks are managed to provide for separation of duties. When separation of duties is utilized in the workflow environment, some amount of delay is generally acceptable between tasks.

However, there is a need to be able to protect particular data or an individual task from a compromised authorized individual. It is also necessary to be able to provide this protection with no or minimal disruption to the abilities of the authorized individuals to perform the tasks they need to perform for which they need access to the information or system. This requires a solution that is non-disruptive to the tasks that need to be completed, as automated as possible, and that can occur in near real time.

There is therefore a need to provide a technique to substantially prevent the ability of a single authorized individual to access a computer system or data which overcomes the various drawbacks of these aforedescribed prior techniques. There is also a need to provide a technique for this protection in which authorization can take place in near real time.

SUMMARY OF THE INVENTION

The present invention is analogous to a safe deposit box where the box owner has one key (authorization) to open the box but still needs the bank manager to approve of the opening of the box by using their second key (authorization) before the box can be opened. Without both the box owner and the bank manager agreeing that the box should be opened (by providing their keys), the box does not get opened. The present system provides the infrastructure needed to require multiple parties to authorize a specific task before it can be performed.

In one embodiment, a method of securing access to computer system resources by requiring multiple party authorization before access to the resources is granted comprises the following steps. A networked computer system is provided that comprises a requestor interface connected to an authorization agent wherein the authorization agent is adapted to control access to resources contained in a protected device. An authorization server is connected to the authorization agent. A policy engine is connected to the authorization server, wherein the policy engine determines what resources contained in the protected device will have restricted access and the requirements for the access. Each request for access from a requestor to a resource that the policy engine has predetermined will have restricted access requires authorization for access through the authorization server from an authorizer substantially simultaneously with each request for access.

In another embodiment, a network computer system for restricting access to resources contained in a protected device comprises a requestor interface connected to a protected device. An authorization agent is connected to a requestor interface and to the protected device, wherein the authorization agent is adapted to control access to resources contained in the protected device. An authorization server is connected to the authorization agent. A policy engine is connected to the authorization server, wherein the policy engine determines what resources contained in the protected device will have restricted access and the requirements for the access. An authorizer connected to the authorization server for providing authorization for access to a resource is predetermined by the policy engine. The authorizer further provides authorization for access substantially simultaneously with a request for access by a requestor.

BRIEF DESCRIPTION OF THE DRAWINGS

FIG. 1 is a high-level flow chart demonstrating an exemplary system in accordance with the present invention.

FIG. 2 is a flow chart demonstrating interaction of a policy engine in the security system.

FIGS. 3-5 are flow charts demonstrating operation of the second party authorization.

FIGS. 6 and 7 are flow charts of operation of a task request and authorization.

DETAILED DESCRIPTION

The present invention is a method and related system for computer security. The system requires multiple parties to each authorize a task before final authorization is granted. This access control system operates in substantially real time.

At least some of the following discussion makes reference to a particular system that embodies many of the features described herein. The particular system is referred to as the Key2 Technology™. Of course, the present invention is not limited to the specific embodiment referred to herein as “Key 2™”.

The present system and method have the capability to operate in near real time, just as both the box owner and the bank manager need to be present with their keys to open the safe deposit box. One of the challenges that the system overcomes is providing for timely communication to a 2^(nd) party authorizer (bank manager) when the user requesting access (box owner) is attempting to perform the task. With the present computer system, the policy could require a second party to approve the task substantially simultaneously when access to a task is attempted—i.e., the approval needs to happen in near real time.

While Key2 Technology™, one example of the present invention, can be integrated with any of the access control models in widespread use, it fits particularly well with the “Usage Control” model. The Usage Control model includes the concept of obligations that need to be satisfied before a task is authorized or for a task to remain authorized. Requiring a second party to approve a task before it can be performed fits nicely within the obligations component of the model. The Usage Control Model allows for the expansion of discretionary access control models, mandatory access control models, and role-based access control models to support Key2 Technology™.

Multi-party authorization will proactively require two people to know and approve critical actions before they take effect. This is a radical improvement over current approaches that often only provide logs for later analysis.

Key2 Technology™ provides sensitive and critical network, computer system, and database operations with greater levels of security than ever before. The challenge is to enable a network administrator to do their job efficiently while at the same time protecting the network against a compromised administrator or requestor for access to a network resource. Key2 Technology™ provides for dynamic policy changes, including what resources to protect and what parties to utilize as authorizers, managed from a central location. Near real-time communication between the party initiating the task (requestor), the Key2™ system, and the 2^(nd) party approver of the task (authorizer) is an integral part of the Key2™ system.

Key2™ Technology provides for both centralized policy management and multi-party authorization request processing. Policy management includes tracking the resources or tasks (collectively referred to as “resources” or “tasks”) that require multi-party authorization and tracking who the authorizers are for those tasks. The Key2™ policy engine synchronizes with the database of resources that are to be protected on each of the distributed Key2™ servers. The Key2™ servers will register the categories of protected resources with the Key2™ agents for which the agents will need to request authorization from the Key2™ server. The policy engine will push the information to the Key2 servers to enable them to determine the proper set of authorizers to choose from for a requested task.

The Key2 Technology™ architecture as shown in FIG. 1 includes several components and interfaces. They include:

Key2™ Authorization Agent (AuthA) module runs on the system that protects the resources (specific, predetermined files) with Key2 Technology.

Key2™ AuthA Application Programming Interface (API) allows the resource manager of the protected resource to utilize Key2 Technology™.

Key2™ Authorization Server (AuthS) runs on various servers in the management network to handle authorization requests from the authorization agents. From the information in the authorization request and the information in the authorization information database (AID) including policy information, the AuthS will determine the best authorizer to attempt to contact and coordinate the contact.

Key2™ A-S is the protocol for interactions between the authorization agents (AuthA) and the authorization servers (AuthS).

Key2™ Authorization Information Database (AID) defines the structure of the information that needs to be stored in order to provide for Key2™ authorization.

Key2™ Contact Plug-ins interact with a specified authenticator. Plug-ins for Instant Messenger, E-Mail, mobile and fixed-line, Phone, PDA are all possible.

Key2™ C-S is the protocol for interactions between the authorization server (AuthS) and the Contact plug-ins.

Key2™ Policy Engine updates the Authorization Policy Database (APD) and synchronizes all of the authorization servers (AuthS) modules with the current APD.

Key2™ Authorization Policy Database (APD) defines the policy information and the structure of that information that needs to be saved for the Key2™ authorization system.

Key2™ Policy API defines the interface for configuration and update of authorization policy for the Key2™ authorization system.

Decisions on what tasks or resources (e.g. sensitive files) need to be protected with multi-party authorization are made at a user interface to the Key2 policy engine. Policy on which resources or tasks to protect with Key2 can be based on a wide variety of attributes of the resource or task as well as on environmental factors. Some exemplary attributes of tasks might include disruptiveness and criticality among others. For example, if there is a task called “reload”, it might have attribute disruptiveness=10 (Very High). If this for the task on a router supporting the stock exchange it might have criticality=8 (High), but if it is for the task on a router in a test lab it might have criticality=0 (Very Low). Policy can be set for classes of resources or tasks, or for specific resources or tasks. Another attribute will be the name of an authorizer list and a priority for contact with respect to authorization.

An example of how environmental factors can play a role would include the status of a device. It would be possible to define a status for a device or resource than included values such as production, non-disruptive test, disruptive test, or maintenance, among others. If the resource is in production status it might require multi-party authorization to perform the “reload” task, while if the resource is in maintenance status the “reload” task might not require multi-party authorization.

As shown in FIG. 2, the Key2 policy engine will distribute the information on resources to be protected by multi-party authorization to the Key2 servers. The Key2 servers will store this information in their authorization information database. They also will communicate with the Key2 agents informing them of the resources or tasks they should be protecting with multi-party authorization or instructing the Key2 agents to always query the Key2 servers for particular classes of tasks or resources. The Key2™ agent will maintain the definitions of resources or tasks that require multi-party authorization and communicate multi-party authorization requests to the Key2 Servers.

As shown in FIG. 3, definitions of who is able to provide second party authorization is also defined at a user interface to the Key2 policy engine. An authorizer list and authorizer records are created that provides a list of parties eligible to provide 2^(nd) party authorization, contact information on methods to contact the authorizer including a list of current preferred order of methods of contact, hours responsible for providing authorization, authorizer status, and a preferred priority list ordering which authorizer to attempt to contact first. Another option is to specify attempting to contact multiple authorizers simultaneously.

As shown in FIG. 4, an authorizer communicates with the Key2 system through a Contact Plugin. Plugins will be developed for a number of communications media. An authorizer can contact the Key2 system and update select information in their authorizer record which will also be reflected in the authorizer lists. Examples of the type of information an authorizer will be able to modify includes their status, contact methods, and preferred order of contact methods.

The resource managers for the protected resources will need to call on the Key2™ authorization agent (AuthA). In some cases, this may be a stand-alone add-on. In other cases it might be necessary or preferable to have the Key2™ authorization calls integrated into the security kernel. Some of the most obvious resource managers for inclusion of Key2 Technology™ include operating systems (including configuration and management subsystems), file systems, and data base systems.

As shown in FIG. 5, the first step in the process is for a person (the “requestor”), using a requestor interface, to seek access to a particular resource. When a Key2™ agent determines that an authorization request requires multi-party authorization, it forwards the information needed for the authorization decision to the Key2™ server. If the server concurs that multi-party authorization is required, the server determines the preferred authorizer(s) for the task and utilizes the appropriate contact plug-in to provide them with the needed information. Some of the included information could include, the task to be performed, the resource it is to be performed on, the party (requestor) attempting to perform the task, any comments they elected to enter, and contact information for the party initiating the task in case the authorizer requires a conference with the task initiator before making an authorization decision. The authorizer then replies to the server through the contact plug-in with the authorization decision. The server passes this decision to the agent and then ultimately to the requestor.

The flow of a multi-part authorization request on a Key2™ Authorization Agent is exemplified by the flowchart shown as FIG. 6.

An authorization request flow on a Key2™ Server is exemplified by the flowchart shown as FIG. 7.

Integration of Key2 Technology™ into the security kernel of operating systems of computers and network equipment, file systems, and database managers adds significant value to those systems when used in a secure environment. It allows management to require and set multi-party authorization for execution of certain commands, read or write access to certain files, and read or write access to certain fields of a database. With the appropriate policy in place, one authorized individual will no longer be able to shut down a critical server, read the entire database of customer credit card numbers, or launch a test procedure in the production network that could take the entire network down. Some of the most destructive attacks that have occurred and some of our most dangerous vulnerabilities are addressed with Key2 Technology™.

Multi-party authorization greatly improves security, but to be effective any associated overhead must be kept to a minimum. Key2 Technology™ provides the security that comes from multi-party authorization™ while at the same time limiting its burden. The Key2 Technology™ architecture provides a workable distributed multi-party authorization™ system for resource control.

While the invention has been described with reference to specific embodiments thereof, it will be understood that numerous variations, modifications and additional embodiments are possible, and all such variations, modifications, and embodiments are to be regarded as being within the spirit and scope of the invention. 

1. A method of securing access to computer system resources by requiring authorized user requesters requesting access to the resources to undergo one or more additional authorization before access to the resources is granted, the method comprising the steps of: providing a networked computer system comprising an authorization agent with an operatively associated requestor interface wherein the authorization agent is adapted to control access to one or more resources operatively associated with a protected device, providing an authorization server communicatively associated with the authorization agent, providing a policy engine communicatively associated with the authorization server, wherein the policy engine determines what resources operatively associated with protected device require additional authorization for access and requirements for the access; and for each request from an authorized user requester to the authorization agent for access to a resource that the policy engine has predetermined will require additional authorization for access, performing the steps of; the requester interface communicating, in near real time, to the authorization agent a request for access by an authorized user requestor to the resource; the authorization agent communicating, in near real time, to the authorization server the request for additional authorization; the authorization server selecting, from a group of authorizers, one or more authorizers, to make an additional authorization decision; the authorization server communicating in near real time the request for additional authorization to the one or more authorizers; the authorizer deciding the additional authorization to be granted; the authorizer communicating, in near real time, the authorization decision to the authorization server; the authorization server communication in near real time the authorization decision to the authorization agent; and the authorization agent controlling the authorized user requestor's access to the resource based upon the additional authorization decision from the authorizer.
 2. The method as described in claim 1, further comprising providing a plurality of said networked computer system.
 3. The method as described in claim 1, comprising providing a plurality of authorization servers communicatively associated with the authorization agent.
 4. The method as described in claim 3, wherein the policy engine determines which specific authorizers are a part of the group of authorizers from which the authorization server will select the authorizers for each request for access.
 5. The method as described in claim 3, wherein the policy engine determines the protocol to be used for contacting the authorizers with respect to each request for access.
 6. The method as described in claim 3, wherein the policy engine periodically updates an authorization database and synchronizes all of the authorization servers with the updated authorization database.
 7. The method as described in claim 1, further comprising requiring a requestor to have authority to access the requestor interface.
 8. The method as described in claim 1, wherein the authorization server contacts an authorizer through a contact plug-in selected from the group consisting of instant messenger, e-mail, mobile and fixed line phones, and personal digital assistants.
 9. A system for restricting access to resources contained in a protected device, the system comprising: an authorization agent, with an operatively associated requestor interface and communicatively associated with a protected device, wherein the authorization agent is adapted to control access to one or more resources operatively associated with the protected device; an authorization server communicatively associated with the authorization agent; a policy engine communicatively associated with the authorization server, wherein the policy engine determines what resources operatively associated with the protected device require additional authorization of authorized users and requirements for the access; and an authorizer communicatively associated with the authorization server for providing authorization decisions for access to the resource, wherein the authorizer is selected from a group of authorizers determined by the policy engine, and further wherein the authorization agent communicates an additional authorization request to the authorization server in near real time, the authorization server communicates the additional authorization request to the authorizer in near real time, the authorizer communicates an authorization decision to the authorization server in near real time, the authorization server communicates the authorization decision to the authorization agent in near real time, and the authorization agent controls the authorized user requestor's access to the resource based upon the authorization decision.
 10. A system as described in claim 9, further comprising a plurality of authorization agents.
 11. A system as described in claim 9, further comprising a plurality of authorization servers operatively associated with the authorization agent.
 12. A system as described in claim 11, wherein the policy engine determines which specific authorizer are a part of the group of authorizers from which the authorization server will select the authorizers for each request for access.
 13. A system as described in claim 11, wherein the policy engine determines the protocol for contacting authorizers with respect to each request for access.
 14. A system as described in claim 9, further comprising contact plug-ins operativel associated with the authorization server and communicatively associated with the authorizers, the contact plug-ins selected from the group consisting of instant messenger, e-mail, mobile and fixed line phones, and personal digital assistants.
 15. A system for restricting access to one or more resources operatively associated with a protected device, the system comprising: interface means for communicatively associating an authorized user requestor with a protected device; an authorization agent operatively associated with the interface means and the protected device, wherein the authorization agent is adapted to control access to one or more resources operatively associated with the protected device; an authorization server communicatively associated with to the authorization agent; a policy engine communicatively associated with the authorization server, wherein the policy engine comprises means for determining what resources operatively associated with the protected device require additional authorization of authorized users and requirements for the access; means for communicatively associating an authorizer with the authorization server to provide authorization decisions for access; wherein an additional authorization request is communicated from the authorization agent to the authorization server in near real time; wherein the authorization server selects one or more authorizers from a group of authorizers, the group of authorizers for the request determined by the policy engine; wherein the additional authorization reguest is communicated from the authorization server to the authorizer in near real time; wherein the authorization decision is communicated from the authorizer to the authorization sewer in near real time; wherein the authorization decision is communicated from the authorization server to the authorization agent in near real time; and wherein the authorization agent enforces the authorization decision for the access request by the authorized user to the resource. 